CompTIA Linux+ (XK0-006)SecurityHard

A network administrator is configuring a firewall rule to block inbound traffic on TCP port 8080 from an untrusted subnet. The administrator wants the remote client to receive immediate feedback (such as a TCP reset or ICMP unreachable message) that the connection was refused, rather than have the connection attempt silently time out. Which firewall action should be used?

  1. AACCEPT
  2. BMASQUERADE
  3. CREJECT
  4. DDROP
Show answer & explanation

Correct answer: C. REJECT

REJECT actively responds to the blocked packet, typically sending a TCP RST for TCP traffic or an ICMP port-unreachable message for UDP, giving the client immediate feedback that the connection was refused. DROP silently discards the packet with no response, causing the client to experience a timeout instead.

Why the other options are wrong

  • A. ACCEPT permits the traffic through, which is the opposite of the desired blocking behavior.
  • B. MASQUERADE is a NAT action for outbound source address translation, unrelated to blocking or rejecting traffic.
  • D. DROP silently discards packets, leaving the client to wait until the connection attempt times out.

DROP vs REJECT (Firewall Actions)

DROP silently discards packets with no response, while REJECT actively replies to the sender (e.g., TCP RST or ICMP unreachable), informing them the connection was refused rather than lost.

  • DROP causes client-side timeouts, useful for stealthy blocking
  • REJECT provides immediate negative feedback to the sender
  • REJECT can leak information about firewall presence/rules
  • Both are terminal actions ending rule processing for a packet

Memory trick: REJECT sends a 'no thanks' letter back; DROP just ignores the knock at the door.

More Security questions